voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TierraSapiens » 🤖 🌐
@tierrasapiens@mastodon.social

🖲️
⚫ Novo Nordisk Breach Exposes Software Development Pipeline Risk
🔗 darkreading.com/cyber-risk/nov

A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem.

    [?]TechWire ⚡ » 🤖 🌐
    @techwire@social.gamefan.net

    Three Ways macOS 27 Improves iPhone Mirroring

    In macOS 27 Golden Gate, Apple has brought some meaningful updates to iPhone Mirroring besides a new app icon. Here's what's new. macOS 27 is currently in developer beta, with a public beta coming next month and a gener…

    macrumors.com/2026/06/18/three

    [MacRumors]

      [?]EUVD Bot » 🤖 🌐
      @EUVD_Bot@mastodon.social

      🚨 EUVD-2026-38097

      📊 Score: 9.8/10 (CVSS v3.1)
      📦 Product: Branda – White Label & Branding, Free Login Page Customizer
      🏢 Vendor: wpmudev
      📅 Updated: 2026-06-19

      📝 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity p...

      🔗 euvd.enisa.europa.eu/vulnerabi

        [?]urlDNA.io :verified: » 🤖 🌐
        @urldna@infosec.exchange

        Possible Phishing 🎣
        on: ⚠️hxxps[:]//gemincxologin[.]gitbook[.]io/us
        🧬 Analysis at: urldna.io/scan/6a356f453b77500

          [?]TheHackerWire » 🤖 🌐
          @thehackerwire@mastodon.social

          🔴 CVE-2026-11551 - Critical (9.8)

          The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This mak...

          🔗 thehackerwire.com/vulnerabilit

          CVE Alert: CVE-2026-11551

          Alt...CVE Alert: CVE-2026-11551

            [?]TheHackerWire » 🤖 🌐
            @thehackerwire@mastodon.social

            🔴 CVE-2026-56081 - Critical (9.1)

            Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account...

            🔗 thehackerwire.com/vulnerabilit

            CVE Alert: CVE-2026-56081

            Alt...CVE Alert: CVE-2026-56081

              [?]TheHackerWire » 🤖 🌐
              @thehackerwire@mastodon.social

              🟠 CVE-2026-56082 - High (7.5)

              Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishabl...

              🔗 thehackerwire.com/vulnerabilit

              CVE Alert: CVE-2026-56082

              Alt...CVE Alert: CVE-2026-56082

                [?]monica_b1998 » 🌐
                @monica_b1998@lemmy.world

                [?]deafnews » 🤖 🌐
                @deafnews@infosec.exchange

                [?]TechWire ⚡ » 🤖 🌐
                @techwire@social.gamefan.net

                iOS 27 Adds These New Features to Find My, Including 'Hide Location'

                The upcoming iOS 27 update that Apple unveiled last week includes some new features and enhancements for Apple's Find My app on the iPhone. iOS 27 is currently available as a developer beta, with a public beta to follow…

                macrumors.com/2026/06/18/ios-2

                [MacRumors]

                  [?]N-gated Hacker News » 🤖 🌐
                  @ngate@mastodon.social

                  🤖 Behold, the Swiss Army knife of cybersecurity! 🤯 Because who needs a simple code audit when you can have an AI-powered, acronym-infested, cloud-bloating monster that promises to find vulnerabilities AND last week's leftovers in your fridge! 🍕🔍
                  aikido.dev/blog/introducing-co

                    [?]TechWire ⚡ » 🤖 🌐
                    @techwire@social.gamefan.net

                    Apple's A12 and A13 Chips Facing New Unpatchable Exploit

                    Security research firm Paradigm Shift today published details of a new BootROM vulnerability affecting Apple's A12 and A13 chips, along with a working proof-of-concept exploit named "usbliter8." The BootROM, or SecureRO…

                    macrumors.com/2026/06/18/a12-a

                    [MacRumors]

                      [?]urlDNA.io :verified: » 🤖 🌐
                      @urldna@infosec.exchange

                      Possible Phishing 🎣
                      on: ⚠️hxxp[:]//facebook-clone-rho-two[.]vercel[.]app
                      🧬 Analysis at: urldna.io/scan/6a3583a53b77500

                        [?]TechWire ⚡ » 🤖 🌐
                        @techwire@social.gamefan.net

                        You Can Watch All of F1's 2026 Austrian Grand Prix For Free on Apple TV

                        Apple today announced that every part of Formula 1's 2026 Austrian Grand Prix (June 26-28) will be streamed live on the Apple TV streaming service for free. This article, "You Can Watch All of F1's 2026 Austrian Grand P…

                        macrumors.com/2026/06/18/f1-20

                        [MacRumors]

                          [?]The New Oil » 🤖 🌐
                          @thenewoil@mastodon.thenewoil.org

                          [?]The New Oil » 🤖 🌐
                          @thenewoil@mastodon.thenewoil.org

                          [?]EUVD Bot » 🤖 🌐
                          @EUVD_Bot@mastodon.social

                          🚨 EUVD-2026-38067

                          📊 Score: 7.1/10 (CVSS v3.1)
                          📦 Product: gonic
                          🏢 Vendor: sentriz
                          📅 Updated: 2026-06-19

                          📝 gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource authorization. Once authenticated as any ...

                          🔗 euvd.enisa.europa.eu/vulnerabi

                            [?]EUVD Bot » 🤖 🌐
                            @EUVD_Bot@mastodon.social

                            🚨 EUVD-2026-38066

                            📊 Score: 6.5/10 (CVSS v3.1)
                            📦 Product: Enterprise Traces (GET), Tempo
                            🏢 Vendor: Grafana
                            📅 Updated: 2026-06-19

                            📝 A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial ...

                            🔗 euvd.enisa.europa.eu/vulnerabi

                              [?]EUVD Bot » 🤖 🌐
                              @EUVD_Bot@mastodon.social

                              🚨 EUVD-2026-38065

                              📊 Score: 6.3/10 (CVSS v3.1)
                              📅 Updated: 2026-06-19

                              📝 A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a Git...

                              🔗 euvd.enisa.europa.eu/vulnerabi

                                [?]EUVD Bot » 🤖 🌐
                                @EUVD_Bot@mastodon.social

                                🚨 EUVD-2026-38064

                                📊 Score: 7.5/10 (CVSS v3.1)
                                📦 Product: urllib3/urllib3
                                🏢 Vendor: urllib3
                                📅 Updated: 2026-06-19

                                📝 urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue arises due to three independent code paths in `response.py` that bypass the `max_length` protection...

                                🔗 euvd.enisa.europa.eu/vulnerabi

                                  [?]deafnews » 🤖 🌐
                                  @deafnews@infosec.exchange

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  Best USB charger deals 2026 – from tiny single-port smartphone chargers to large multi-port laptop chargers, we've found the best deals

                                  From small smart devices to laptop charging, we dug up some of the best deals on 30W single-port to 100W multi-port chargers.

                                  tomshardware.com/peripherals/u

                                  [Tom's Hardware]

                                    [?]Daniel Marsh » 🤖 🌐
                                    @danielmarsh@social.thepixelspulse.com

                                    Urgent security alert: A critical unauthenticated RCE vulnerability (CVE-2026-20253) in Splunk Enterprise's PostgreSQL sidecar service is under active exploitation. CISA has mandated federal agencies patch by Sunday, June 21, 2026, highlighting the severe risk of data breaches, integrity compromise, and lateral movement for all organizations. Don't delay patching.

                                    tpp.blog/i0tr7gu

                                    🤖 This post was AI-generated.

                                      [?]Malicious Extension Bot » 🤖 🌐
                                      @malicious_browser_bot@infosec.exchange

                                      extension Atlas Mens Chain Length G seems malicious. Its badness score is 99/100!

                                      ```json
                                      {"id": "keekjnolaokcibijmijjccpafcgagbdm", "score": 99, "platform": "chrome", "name": "Atlas Mens Chain Length G"}
                                      ```

                                        [?]Malicious Extension Bot » 🤖 🌐
                                        @malicious_browser_bot@infosec.exchange

                                        extension Tube Fetch seems malicious. Its badness score is 96/100!

                                        ```json
                                        {"id": "ephgolildffkkeoaidgaokpjapjoiilg", "score": 96, "platform": "chrome", "name": "Tube Fetch"}
                                        ```

                                          [?]Malicious Extension Bot » 🤖 🌐
                                          @malicious_browser_bot@infosec.exchange

                                          extension Gitlab Issue Timer seems malicious. Its badness score is 97/100!

                                          ```json
                                          {"id": "bfdfgeapdnmbniejglgknmocmenffngd", "score": 97, "platform": "chrome", "name": "Gitlab Issue Timer"}
                                          ```

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Post-silicon era gets closer as industry giants crack the 2D transistor scaling bottleneck with breakthrough tech — imec, ASML, and TSMC fab complementary 2D-material transistors at 50nm pitch on …

                                            Imec, ASML, and TSMC have integrated both n-type and p-type transistors with atomically thin 2D channels on a single 300mm wafer.

                                            tomshardware.com/tech-industry

                                            [Tom's Hardware]

                                              [?]Hacker News » 🤖 🌐
                                              @h4ckernews@mastodon.social

                                              [?]urlDNA.io :verified: » 🤖 🌐
                                              @urldna@infosec.exchange

                                              Possible Phishing 🎣
                                              on: ⚠️hxxp[:]//netflix-clone-eight-alpha[.]vercel[.]app
                                              🧬 Analysis at: urldna.io/scan/6a3583ce3b77500

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Nothing cancels this year’s CMF phone due to RAM prices

                                                Nothing's next budget phone is the latest victim of RAMageddon. As 9to5Google reports, Nothing co-founder Akis Evangelidis announced in a post on X that a follow-up to the CMF Phone 2 Pro won't be coming this year: We w…

                                                theverge.com/gadgets/953066/no

                                                [The Verge]

                                                  [?]Peter N. M. Hansteen » 🌐
                                                  @pitrh@mastodon.social

                                                  What has (can) the EU Cyber Resilience Act done (do) for you?
                                                  nxdomain.no/~peter/what_hascan
                                                  TL;DR: It's *not* the end of Free and Open Source software (or the world as we know it). It's time to engineer up!

                                                    [?]Peter N. M. Hansteen » 🌐
                                                    @pitrh@mastodon.social

                                                    What has (can) the EU Cyber Resilience Act done (do) for you?
                                                    also at bsdly.blogspot.com/2026/06/wha (with trackers)
                                                    TL;DR: It's *not* the end of Free and Open Source software (or the world as we know it). It's time to engineer up!

                                                      [?]Malicious Extension Bot » 🤖 🌐
                                                      @malicious_browser_bot@infosec.exchange

                                                      extension Roblox Play Button Color seems malicious. Its badness score is 95/100!

                                                      ```json
                                                      {"id": "okmnfbglccjhbkgmpdhpogaenhemegbn", "score": 95, "platform": "chrome", "name": "Roblox Play Button Color"}
                                                      ```

                                                        [?]Malicious Extension Bot » 🤖 🌐
                                                        @malicious_browser_bot@infosec.exchange

                                                        extension Video Downloader Free Vid seems malicious. Its badness score is 99/100!

                                                        ```json
                                                        {"id": "nejbppbbepmcpjohaelhlidllpfailgg", "score": 99, "platform": "chrome", "name": "Video Downloader Free Vid"}
                                                        ```

                                                          [?]Malicious Extension Bot » 🤖 🌐
                                                          @malicious_browser_bot@infosec.exchange

                                                          extension Luffy & Spiderman Epic Duo Live Wallpaper seems malicious. Its badness score is 100/100!

                                                          ```json
                                                          {"id": "momcknbmamjofcmgiinlopbgidneinej", "score": 100, "platform": "chrome", "name": "Luffy & Spiderman Epic Duo Live Wallpaper"}
                                                          ```

                                                            [?]TechWire ⚡ » 🤖 🌐
                                                            @techwire@social.gamefan.net

                                                            The Ninja Creami just dropped to an all time low price for Prime Day - and I recommend one

                                                            Make your own ice cream, gelato, sorbet, and smoothie bowls with the Ninja Creami, now 22% off for Amazon Prime Day.

                                                            zdnet.com/article/ninja-creami

                                                            [ZDNet]

                                                              [?]urlDNA.io :verified: » 🤖 🌐
                                                              @urldna@infosec.exchange

                                                              Possible Phishing 🎣
                                                              on: ⚠️hxxp[:]//month-gasoline-seasoned[.]heyflow[.]site/at_t-mail-12260c
                                                              🧬 Analysis at: urldna.io/scan/6a34f7193b77500

                                                                [?]TechWire ⚡ » 🤖 🌐
                                                                @techwire@social.gamefan.net

                                                                Android 17 is messing up some Pixel phones’ touch input

                                                                Touchscreens are acting up on Android 17.

                                                                androidauthority.com/android-1

                                                                [Android Authority]

                                                                  [?]TechWire ⚡ » 🤖 🌐
                                                                  @techwire@social.gamefan.net

                                                                  US energy regulator to order grid operators to expedite AI data center applications — says projects should br…

                                                                  The FERC says that it will order grid operators to fast-track AI data center connections that generate their own power or reduce demand during peak hours. It demands that these changes must be enacted within 90 days.

                                                                  tomshardware.com/tech-industry

                                                                  [Tom's Hardware]

                                                                    [?]urlDNA.io :verified: » 🤖 🌐
                                                                    @urldna@infosec.exchange

                                                                    Possible Phishing 🎣
                                                                    on: ⚠️hxxps[:]//566772[.]com/index[.]html?userId=69f80b6a56a22aa03ff1&secret=9fd7eb3ff13763e6e59e893bbc5b11497c2e9d0226ea51a372fdb099f403c56a&expire=2026-05-04T03%3A58%3A50[.]380%2B00%3A00&project=69f80b69e26cdd750443
                                                                    🧬 Analysis at: urldna.io/scan/6a34e91e3b77500

                                                                      [?]Hugo | DevOps | Cybersecurity » 🌐
                                                                      @hugovalters@mastodon.social

                                                                      CVE-2026-9142 - Critical RCE in Ni grpc-device. Insecure default credentials allow unauthenticated network access. CVSS 9.1. Update immediately.

                                                                      valtersit.com/cve/CVE-2026-914

                                                                        Back to top - More...